CVE-2024-55271: Phpgurukul Gym Management System

Low severity, CVSS 3.5. EPSS: 0.1% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in phpgurukul Gym Management System 1.0. This issue is present in the profile update functionality of the User Panel, specifically the /profile.php endpoint.

Affected products

  • Phpgurukul Gym Management System: version 1.0 only

Published 2026-02-17. Last modified 2026-06-17.